Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 13:14 UTC. Ordered by latest scan.
The inspected lifecycle chain performs unconsented writes to global Gemini instructions and Claude configuration, meeting the supplied blocking rule for foreign AI-agent control surfaces....
Source establishes unconsented postinstall mutation of broad foreign AI-agent control surfaces, meeting the supplied blocking policy. Package-aligned functionality and partial configurati...
The inspected automatic install chain mutates foreign, global AI-agent control surfaces without consent, meeting the supplied blocking policy. Package ownership of the embedded skills and...
Source proves unconsented npm lifecycle mutation of global Claude Code command settings, including replacement of existing commands. This meets the supplied blocking rule independently of...